# The "sonic-traffic" index pattern does not contain any of the following field types: geo\_point

**URL:** <https://discuss.elastic.co/t/the-sonic-traffic-index-pattern-does-not-contain-any-of-the-following-field-types-geo-point/119849>\
**Category:** Logstash\
**Created:** [February 14, 2018, 5:15pm UTC](https://discuss.elastic.co/t/the-sonic-traffic-index-pattern-does-not-contain-any-of-the-following-field-types-geo-point/119849 "2018-02-14T17:15:21Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![legolas\_bilbao](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@legolas\_bilbao](https://discuss.elastic.co/u/legolas_bilbao)\
**Post date:** [February 14, 2018, 5:15pm UTC](https://discuss.elastic.co/t/the-sonic-traffic-index-pattern-does-not-contain-any-of-the-following-field-types-geo-point/119849/1 "2018-02-14T17:15:21Z")

</div>

Good morning,

I've come back to test Elasticsearch and its works like i like but the option of geoip doesnt work.

Logstash filter file

if [type]=="sonicwall"{

```
             kv {
                    exclude_keys => ["c", "id", "m", "n", "pri"]
            }
            grok {
                    match => ["src", "%{IP:srcip}:%{NUMBER:srcPort}:(?<srcInterfaz>X[0-9][-]V[0-9]{1,3}|X[0-9])" ]
            }
            grok {
                    match => ["dst", "%{IP:dstip}:%{NUMBER:dstPort}:(?<dstInterfaz>X[0-9][-]V[0-9]{1,3}|X[0-9])" ]
            }
    }
    geoip {
             source => "dstip"
             add_tag => ["DSTgeoip"]
             add_field => ["[DSTgeoip][coordinates]", "%{[geoip][longitude]}"]
             add_field => ["[DSTgeoip][coordinates]", "%{[geoip][latitude]}" ]
          }

```

Template

> "geoip" : {  
> "dynamic": true,  
> "properties" : {  
> "ip": { "type": "ip" },  
> "location" : { "type" : "geo\_point" },  
> "latitude" : { "type" : "half\_float" },  
> "longitude" : { "type" : "half\_float" }  
> }  
> }

Going to the kibana index

 ![coordenadas](https://us1.discourse-cdn.com/elastic/original/3X/3/2/3249b3f242901d6c323b056bdbc43b6f4959ae3f.JPG)

compare with the tutorial in the tutorial coordinates appears between and in my model no.

any idea what im doing wrong?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 18, 2018, 2:10pm UTC](https://discuss.elastic.co/t/the-sonic-traffic-index-pattern-does-not-contain-any-of-the-following-field-types-geo-point/119849/2 "2018-02-18T14:10:44Z")

</div>

Your index template configures `[geoip][location]` to be a geo\_point field. If you want `[DSTgeoip][coordinates]` to be a geo\_point field you need to adjust your template accordingly.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 18, 2018, 2:10pm UTC](https://discuss.elastic.co/t/the-sonic-traffic-index-pattern-does-not-contain-any-of-the-following-field-types-geo-point/119849/3 "2018-03-18T14:10:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
